CVE-2026-25687 | Zscaler Client Connector prior 4.6.0.486/4.7.0.350/4.8.0.267/4.9.0.412 ZPA tunnel handler race condition

SecurityVulns

A vulnerability has been found in Zscaler Client Connector and classified as very critical. Affected is an unknown function of the component ZPA tunnel handler. This manipulation causes race condition.

This vulnerability is tracked as CVE-2026-25687. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More